regulations

High-Risk AI System

An AI system subject to heightened legal obligations because of what it's used for — not because of the underlying technology — typically because it materially affects access to employment, credit, healthcare, housing, or legal standing.

Analysts monitoring a high-risk AI system's outputs on screens
Photo: Abu Saeid via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

"High-risk" is a legal classification, not a technical one — it describes what a system is used for, not what kind of model powers it. A simple logistic regression used to screen job candidates can be high-risk; a large language model used for internal code review generally is not.

How the classification works under the EU AI Act

Under the EU AI Act, a system becomes high-risk through one of two tracks: it's a safety component of a product already covered by existing EU product-safety law, or it falls into one of the specific use-case categories listed in Annex III — employment decisions, creditworthiness evaluation, access to essential services, biometric categorization, and others. See our full breakdown of Article 6 classification for how the two-step test actually applies, including the exemption most teams misuse.

How U.S. state laws draw the line differently

U.S. state laws generally use similar language — "consequential decision," "high-risk artificial intelligence system" — but define the triggering use cases independently, state by state, rather than through a shared list like the EU's Annex III. Colorado's SB 205, for example, defines a high-risk system by reference to consequential decisions in employment, education, lending, housing, healthcare, insurance, and legal services. The categories overlap heavily with the EU's list but aren't identical, which is exactly why a system can be high-risk in one jurisdiction and outside a comparable category in another.

Why the classification is the hinge point

Classification isn't academic — it's the trigger for a specific, often extensive set of obligations: risk management processes, data governance requirements, technical documentation, human oversight measures, and (in most U.S. state frameworks) a documented impact assessment. Getting the classification wrong in either direction has real cost: over-classifying burns compliance resources on systems that don't need it; under-classifying leaves a genuinely consequential system without the safeguards the law requires.

Executives reviewing an AI governance accountability structure in an office
Photo: Vitaly Gariev via Unsplash

ai governance

AI Governance

The structure of accountability, review, and decision rights a company puts in place to control how it builds, buys, and deploys AI systems.
Governome Editorial Team · 2 min read
Software engineers examining model outputs for signs of algorithmic bias
Photo: Samuel Bourke via Unsplash

risk management

Algorithmic Bias

A systematic pattern in a model's outputs that disadvantages a particular group, arising from training data, feature selection, or optimization choices rather than random error.
Governome Editorial Team · 2 min read
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 3 min read
Legal team reviewing duty-of-care obligations under Colorado's AI Act
Photo: Junior Verhelst via Unsplash

regulations us colorado

Colorado AI Act (SB 205)

Colorado's SB 205 imposes duties of reasonable care on both developers and deployers of high-risk AI systems, with impact assessment and consumer notice requirements tied to consequential decisions.
Governome Editorial Team · 2 min read